[Git][security-tracker-team/security-tracker][master] Update status for CVE-2026-19685/network-manager
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Sep 3 05:57:23 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
a14120c6 by Salvatore Bonaccorso at 2026-09-03T06:55:12+02:00
Update status for CVE-2026-19685/network-manager
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -11985,7 +11985,7 @@ CVE-2026-74580 (In the Linux kernel, the following vulnerability has been resolv
- linux 7.1.9-1
NOTE: https://git.kernel.org/linus/de845981da67a6b049080c87e605130b0c30adc5 (7.2-rc7)
CVE-2026-19685 (NetworkManager did not apply the private_user restriction to the 802-1 ...)
- - network-manager <unfixed> (bug #1145199)
+ - network-manager 1.58.1-1 (bug #1145199)
[trixie] - network-manager <not-affected> (Fix for CVE-2025-9615 not applied)
[bookworm] - network-manager <not-affected> (Fix for CVE-2025-9615 not applied)
[bullseye] - network-manager <not-affected> (Fix for CVE-2025-9615 not applied)
@@ -11993,6 +11993,7 @@ CVE-2026-19685 (NetworkManager did not apply the private_user restriction to the
NOTE: Introduced with: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/commit/e85cc46d0b36cdba50fe8411cc93d55a49ebfccf (1.57.1-dev)
NOTE: The introducing commit is part of the patchseries for CVE-2025-9615
NOTE: Fixed by: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/commit/a8e87381a3e70060abd721d9a347f42b2ba68e6e
+ NOTE: Fixed by: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/commit/15aa1a8963ee014f5eb8306b305b158293c10643 (1.58.1)
CVE-2026-9033 (An unauthenticated attacker with network access to the captive portal ...)
NOT-FOR-US: TPLink
CVE-2026-8717
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a14120c67fe4f8200f580adaa33e3520d9487bb0
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a14120c67fe4f8200f580adaa33e3520d9487bb0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260903/b815e9e7/attachment.htm>
More information about the debian-security-tracker-commits
mailing list